For Nepal’s payment industry, the next phase of digital growth will therefore depend not merely on adding more wallet users or recording higher QR transactions. Trust, verifiable customer identity, protection of customer funds, cyber resilience and effective internal controls are becoming just as important as transaction growth. The NRB report suggests that unless these foundations improve alongside adoption, the success of Nepal’s digital-payment expansion could itself magnify the consequences of regulatory and operational weaknesses.

Nepal’s digital payment industry is expanding at a pace that is increasingly testing the ability of payment companies to manage security, customer verification and operational risks. A new oversight report from Nepal Rastra Bank (NRB) shows that weaknesses in Know Your Customer (KYC) verification, internal controls, cybersecurity and settlement practices persist among institutions operating at the heart of the country’s fast-growing digital payment ecosystem.
The concern is particularly significant because digital payments are no longer a marginal part of Nepal’s financial system. As of mid-July 2025, the country had 26.76 million mobile-wallet users, while transactions through mobile wallets amounted to Rs 506.31 billion during the fiscal year. Mobile banking customers reached 27.74 million, up 12.5 percent in a year.
The expansion has been even faster in QR payments. NRB data show that the number of QR-based transactions jumped 92.5 percent in fiscal year 2024/25, while their value increased 91.8 percent. Transactions through faster payment systems also rose 34.6 percent in volume and 33.7 percent in value. QR payments have now emerged as the country's most widely used retail digital payment instrument.
The rapid expansion, however, is exposing weaknesses behind the digital interface used by millions of consumers.
During fiscal year 2024/25, NRB conducted regular on-site inspections of 16 licensed payment institutions and a special inspection of one additional institution. The central bank assessed systemic, operational, settlement and liquidity risks as well as compliance with payment laws and directives. Its findings point to deficiencies in governance, risk-management frameworks, operating procedures and regulatory compliance.
Among the most important findings was the presence of a significant number of customers whose KYC had not been verified. This is more than a documentation problem. KYC is the first layer through which a payment provider establishes who is actually controlling an account or wallet. Weak verification can make it easier for fraudulent or fictitious accounts to enter the financial system and makes suspicious transactions more difficult to trace.
The weakness therefore has implications for anti-money-laundering controls as well. NRB separately noted that the speed and interconnected nature of digital payments have increased exposure to money laundering, terrorism financing and other financial crime risks. The central bank said digital payment platforms had also been misused in activities linked to gold smuggling and money laundering, underscoring the need for stronger customer onboarding and transaction monitoring.
The inspection findings extend well beyond KYC. NRB found cases where internal-control and risk-management policies had not been properly reviewed, anti-money-laundering and counter-terrorist-financing programmes had not been incorporated into annual budgets, and required system audits had not been carried out. Some institutions were also found without adequate disaster-recovery arrangements or regular disaster-recovery drills.
Cybersecurity shortcomings add another layer of concern. The regulator identified instances of antivirus software not being renewed, vulnerability assessment and penetration testing not being conducted for wallet systems, and wallet sessions remaining active without defined expiry periods. Individually, such deficiencies may appear technical, but collectively they can increase exposure to unauthorised access, account compromise, fraud and service disruption.
More serious issues were detected in the handling of customer funds. NRB reported cases where settlement accounts were used for purposes other than settlement and wallet transactions, as well as instances where electronic-money balances exceeded corresponding balances maintained in settlement accounts. The report also identified a case in which a compliance officer had super-administrator privileges and transferred money from a settlement account to wallets—an arrangement the regulator described as a serious governance and control lapse.
These findings are significant because settlement safeguards are designed to ensure that digital money shown in customers’ wallets is properly backed by funds. Weaknesses in this area can therefore create risks that go beyond individual cyberattacks. If controls over backing funds, access privileges and reconciliation are inadequate, problems at a payment provider could potentially affect consumers’ confidence in the wider digital payment system.
NRB’s inspection covered three payment system operators—Gateway Payment Services, Fonepay Payment Service and Smartchoice Technologies—along with PSPs including Khalti, eSewa, We Pay, Nepal Digital Payment Company, Icash, Focusone Payment Solutions, Lenden Sewa, Fintech International, Digi Pay, Nepal Paytime, City Wallet, Chhito Paisa and Smart Card. IME Digital Solution underwent a separate special inspection. The report, however, presents the major inspection deficiencies collectively and does not specify which individual company was responsible for each finding.
The distinction is important. Inclusion in the inspection list should not itself be interpreted as evidence that a particular institution suffered from all—or even any specific one—of the deficiencies highlighted in the consolidated findings.
The central bank has nevertheless taken enforcement action against several PSPs for breaches of payment-related laws, bylaws and directives. During the year, Prabhu Technology, Khalti, Icash and Fintech were warned. Nepal Paytime’s licence was not renewed, while the licences of Paywell Nepal and Sajilo Pay Payment Services were dismissed, according to the report.
Oversight has also extended to the infrastructure used for high-value payments. NRB inspected RTGS-related systems at Himalayan Bank, Shangrila Development Bank, NIC Asia Bank, Nepal SBI Bank, Gurkhas Finance and Shine Resunga Development Bank. The importance of such monitoring has increased as the value of transactions passing through RTGS rose sharply—by 94.4 percent in fiscal year 2024/25.
The findings reveal a broader challenge facing Nepal’s digital finance industry: growth in transaction volume and customer numbers is moving faster than the strengthening of controls at some institutions. Payment companies face pressure to acquire customers, expand merchant networks and introduce new services, but rapid expansion without equivalent investment in KYC, cyber resilience, internal audit, governance and compliance can increase systemic vulnerabilities.
This creates a difficult balance for regulators. Excessively restrictive rules could slow financial inclusion and innovation, while weak supervision could allow fraud, cyber incidents or failures at individual providers to undermine confidence in digital payments. NRB itself acknowledges that digitalisation offers major opportunities for financial inclusion and economic efficiency, but warns that unmanaged risks can weaken consumer trust and the integrity of the payment ecosystem.
The central bank is also working with the National ID and Civil Registration Department toward implementing an electronic KYC system. Linking digital customer verification more closely with reliable identity infrastructure could reduce dependence on manually submitted customer documents and strengthen onboarding, although technology alone will not solve weak governance or inadequate monitoring inside payment companies.
For Nepal’s payment industry, the next phase of digital growth will therefore depend not merely on adding more wallet users or recording higher QR transactions. Trust, verifiable customer identity, protection of customer funds, cyber resilience and effective internal controls are becoming just as important as transaction growth. The NRB report suggests that unless these foundations improve alongside adoption, the success of Nepal’s digital-payment expansion could itself magnify the consequences of regulatory and operational weaknesses.
Written by
Dipesh Ghimire
